peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

401,075 CVEs 1,733 on KEV 17,290 EPSS ≥ 10% 25,091 with exploits synced 2026-10-04

25,091 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2009-0038 EXP Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow re… Patch early 4.3 medium 18% 2009-04-17
CVE-2006-2881 EXP Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execut… Patch early 5.1 medium 18% 2006-06-07
CVE-2006-3266 EXP Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execu… Patch early 5.1 medium 18% 2006-06-27
CVE-2004-0633 EXP The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow. Patch early 5.0 medium 18% 2004-12-06
CVE-2019-8041 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 17.9% 2019-08-20
CVE-2019-8046 EXP Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015… Patch early 9.8 critical 17.9% 2019-08-20
CVE-2021-40651 EXP OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), which can disclose arbitrary fil… Patch early 6.5 medium 17.9% 2021-09-29
CVE-2010-2091 EXP Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a… Patch early 4.3 medium 17.9% 2010-05-27
CVE-2010-1955 EXP Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary f… Patch early 7.5 high 17.9% 2010-05-19
CVE-2001-0053 EXP One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges. Patch early 10.0 high 17.9% 2001-02-12
CVE-2006-5646 EXP Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.1… Patch early 5.0 medium 17.9% 2006-11-01
CVE-2023-39026 EXP Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information… Patch early 7.5 high 17.9% 2023-08-22
CVE-2009-1774 EXP Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via… Patch early 9.3 high 17.9% 2009-05-22
CVE-2019-3921 EXP The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent… Patch early 8.8 high 17.9% 2019-03-05
CVE-2018-11741 EXP NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOT… Patch early 9.8 critical 17.9% 2018-12-26
CVE-2004-1287 EXP Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different… Patch early 10.0 high 17.9% 2005-01-10
CVE-2011-1092 EXP Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (crash) and possibly read se… Patch early 7.5 high 17.9% 2011-03-15
CVE-2006-5645 EXP Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of a… Patch early 5.0 medium 17.9% 2006-11-01
CVE-2007-3554 EXP Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check before 1.5.0.3 allows remote att… Patch early 7.6 high 17.9% 2007-07-04
CVE-2011-2189 EXP net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, wh… Patch early 7.5 high 17.9% 2011-10-10
CVE-2017-0160 EXP Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka… Patch early 7.8 high 17.8% 2017-04-12
CVE-2017-0062 EXP The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 201… Patch early 4.7 medium 17.8% 2017-03-17
CVE-2017-7308 EXP The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which al… Patch early 7.8 high 17.8% 2017-03-29
CVE-2004-0637 EXP Oracle Database Server 8.1.7.4 through 9.2.0.4 allows local users to execute commands with additional privileges via the ctxsys.driload package, which… Patch early 6.5 medium 17.8% 2004-09-02
CVE-2016-4204 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.8% 2016-07-13
CVE-2016-4205 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.8% 2016-07-13
CVE-2016-4206 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.8% 2016-07-13
CVE-2016-4207 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.8% 2016-07-13
CVE-2016-4208 EXP Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befor… Patch early 9.8 critical 17.8% 2016-07-13
CVE-2007-1365 EXP Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragmented IPv6 packets due to "inco… Patch early 10.0 high 17.8% 2007-03-10
← previous page 148 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt